07/30/2026
Some are reporting that this attack originated from Iran. At the time of this post, I have yet to see any official reporting on that. That said here’s why you should care.
The digital space has been both a clandestine and overt battlefield for more than a decade now. This is not new, and public utilities have known about the problem for years. In fact, all the way back in 2012 I was helping local and regional public utilities update their information security technology and practices. Back then the only thing between the control systems and the internet was a firewall developed in the mid 1990's. At that point nothing had changed for twenty years, and most systems were basically naked in a winter storm, wearing nothing but a tee shirt.
Since then, infosec at the public utilities has gotten better, and the states have also been a big help augmenting these micro utilities budgets to strengthen security. What we need to pay attention to is the trend downward. It’s all about time and effort versus effect. Way back in 2012 the big multi-state utilities with brand names on stadiums had already worked hard to lock down their systems. So, the attackers moved downward to regional providers that I worked with. Now that those regional providers put on the winter jacket and are harder to pe*****te, they are reaching all the way down to the local water systems. According to the EPA, something like 97% of water utilities serve 10,000 customers or less, and the very limited staff to match. After the large expense of maintaining those systems, and the limited revenue they generate, there’s not much budget left for security. That’s why they lean so heavily on the state and its programs.
Back to the time versus effort, at the same time it gets harder to attack even these smaller local computer networks, the cost of attacks are going down fast. Before you needed a team of hackers to target public infrastructure like this, now a single hacker can manage a team of "AI agent-hackers". Hundreds of them. For the moment nation states have stayed focused on public infrastructure, that time v effect, but cyber-gangs don’t really care about power or water, they want money. If a cybergang can manage hundreds or thousands of AI agent-hackers, and considering the datacenter costs to go with it, why would they attack a massive company with hardened security when they can attack thousands or tens of thousands of individuals and small businesses? After all, why spend months trying to get past a mega corp’s security system when more than a million SMBs are connected to the internet with only antivirus, developed in the 1990’s, to protect them?
They’ve already done that math and that’s what they’re doing with automated systems today. Around 6,000 SMBs are hit by ransomware every day, but you don’t hear about it much in the news. Auntie Em’s bagel shop shutting down because of ransomware isn’t very splashy news even at the local level, so we never really heard about it, but the stats are there. It’s happening today.
One last takeaway, something not many outside the infosec/defense community are talking about:
What happens when these nation state hackers use AI agent-hackers to target the population directly instead of government services? Let’s say they pick a city like Charlotte, Jacksonville, or Nashville and hack every digital device, hundreds of thousands, maybe millions simultaneously? Your phone’s frozen, your tablet bricked, everything’s completely locked up with ransomware but no one’s asking for money?
I call it the digital nuclear bomb. 1950’s duck and cover antivirus isn’t going to cut it.
More than 30 Minnesota communities saw their water system targeted in a cyberattack that spanned two days, state officials reported on Tuesday.